Manager, Governance, Risk & Compliance

Rochester Regional Health
$115,000 - $140,000Remote

About The Position

The Governance, Risk & Compliance [GRC] Manager at ACM Global Laboratories translates strategic direction into actionable workflows, coordinates cross-functional teams, supports evidence lifecycle management, maps frameworks to control implementation, leads readiness activities, and ensures all ACM GRC processes operate smoothly and efficiently.

Requirements

  • Minimum of 5 years of experience leading Governance, Risk, and Compliance (GRC) programs.
  • Proficiency in ISO 27001

Nice To Haves

  • GRC certifications (e.g. CGRC, CRISC, etc)
  • A bachelor’s degree in IT, cybersecurity, business, or law is preferred, or strong demonstrable background in GRC Management.
  • Previous experience in GRC, risk management, or internal audit, often with a mid-level leadership background.
  • Proficiency in frameworks like SOC2, NIST CSF, and HIPAA regulations.
  • Strong ability to analyze risk data and translate complex regulations into actionable controls.
  • Excellent communication skills to interact with stakeholders and lead team efforts.
  • Experience with 3rd party/vendor risk management processes.
  • Experience in working with sales teams to complete Requests for Proposals and security questionnaires.
  • Understanding of GRC processes such as policy management, risk assessment, and IT audits.
  • Exceptional verbal and written communication skills.

Responsibilities

  • Leads the GRC program activities and a team of professionals related to third-party risk, security internal audit, security compliance, and ISMS program management.
  • Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements.
  • Facilitate regular risk assessments against security frameworks such as SOC 2, ISO 27001, and PCI-DSS, maintain a risk register, and collaborate on mitigation strategies for identified threats. Manage CAPAs for non-compliance.
  • Define specific, assignable actions to mitigate the identified risks or exploit the opportunities.
  • Evaluate how to embed the planned actions directly into daily operational processes.
  • Manage security responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests.
  • Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies. Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises.
  • Build and manage a security metrics (KPI’s) program.
  • Develop relationships with cross-functional teams, understanding their needs in relation to security standards, to drive risk-informed decision-making and build a culture of compliance.
  • Provide expert guidance and support in navigating complex regulatory environments in relation to the management of alignment to ISO-27001 and other applicable security frameworks.
  • Stay updated on applicable industry trends and regulations to ensure ISMS compliance.
  • Monitor and analyze GRC processes and systems, making recommendations for improvement.
  • Document risk reduction plan. Annually, document “Opportunities” (potential positive improvements like adopting some technology for improved efficiency).
  • Other duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service